CVE-2015-4047

Severity
7.8HIGH
EPSS
2.7%
top 14.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 29
Latest updateMay 14

Description

racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages23 packages

Ubuntuipsec-tools< 1:0.8.0-14+deb7u1ubuntu0.1
NVDf5/big-iq_cloud4.0.04.5.0
NVDf5/big-iq_device4.2.04.5.0
NVDf5/big-iq_security4.0.04.5.0

Also affects: Debian Linux 7.0, 8.0, 9.0, Fedora 20, 21, Ubuntu Linux 12.04

🔴Vulnerability Details

3
GHSA
GHSA-47jj-2hp6-grww: racoon/gssapi2022-05-14
CVEList
CVE-2015-4047: racoon/gssapi2015-05-29
OSV
CVE-2015-4047: racoon/gssapi2015-05-22

📋Vendor Advisories

2
Ubuntu
ipsec-tools vulnerability2015-06-01
Red Hat
ipsec-tools: NULL pointer dereference in racoon/gssapi.c2015-05-19

💬Community

1
Bugzilla
CVE-2015-4047 ipsec-tools: NULL pointer dereference in racoon/gssapi.c2015-05-20
CVE-2015-4047 (HIGH CVSS 7.8) | racoon/gssapi.c in IPsec-Tools 0.8. | cvebase.io